ComboFix 09-11-09.01 - Ton Warnaar 10-11-2009 16:40.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.31.1043.18.767.323 [GMT 1:00]
Gestart vanuit: c:\documents and settings\Ton Warnaar\Bureaublad\ComboFix.exe
AV: avast! antivirus 4.8.1356 [VPS 091110-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Desktop_.ini
Besmet exemplaar van c:\windows\system32\drivers\atapi.sys werd aangetroffen en gedesinfecteerd
Hersteld exemplaar van - Kitty ate it
.
(((((((((((((((((((( Bestanden Gemaakt van 2009-10-10 to 2009-11-10 ))))))))))))))))))))))))))))))
.
2009-11-10 15:17 . 2009-11-10 15:17 -------- d-----w- c:\windows\Performance
2009-11-10 15:16 . 2009-11-10 15:16 -------- d-----w- c:\documents and settings\Ton Warnaar\Local Settings\Application Data\Microsoft Corporation
2009-11-10 15:16 . 2009-11-10 15:16 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-11-10 15:15 . 2009-11-10 15:15 22016 ----a-w- c:\windows\system32\tdlwsp.dll
2009-11-09 18:58 . 2009-11-09 20:47 -------- d-----w- c:\program files\a-squared Free
2009-11-05 20:24 . 2009-11-05 20:24 -------- d-----w- c:\documents and settings\Ton Warnaar\Local Settings\Application Data\PCHealth
2009-11-05 19:22 . 2008-02-01 11:55 42376 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
2009-11-05 19:22 . 2007-12-10 13:53 29576 ----a-w- c:\windows\system32\drivers\kcom.sys
2009-11-05 19:22 . 2007-12-10 13:53 81288 ----a-w- c:\windows\system32\drivers\iksyssec.sys
2009-11-05 19:22 . 2007-12-10 13:53 66952 ----a-w- c:\windows\system32\drivers\iksysflt.sys
2009-11-05 19:21 . 2009-11-09 20:04 -------- d-----w- c:\program files\Spyware Doctor
2009-11-05 19:21 . 2009-11-05 19:21 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\PC Tools
2009-11-05 15:50 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-05 15:50 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-05 15:50 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-05 15:50 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-05 15:50 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-05 15:50 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-05 15:50 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-05 15:50 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-05 15:50 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-04 15:10 . 2009-11-04 15:10 -------- d--h--w- c:\windows\PIF
2009-11-04 14:55 . 2009-11-04 14:55 -------- d-----w- c:\windows\system32\WinDefense32
2009-11-04 10:18 . 2009-11-05 17:23 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-04 10:18 . 2009-11-05 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-03 15:33 . 2009-11-03 15:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-11-03 15:01 . 2009-11-03 15:41 -------- d-----w- C:\Spyware Cleaner 2009
2009-11-03 14:54 . 2009-11-03 14:54 -------- d-----w- c:\windows\Sun
2009-11-03 14:14 . 2009-08-27 09:31 16384 ----a-w- c:\windows\system32\drivers\DiagnosticScan.SYS
2009-11-03 14:14 . 2009-10-19 10:21 5120 ----a-w- c:\windows\system32\drivers\Start1Driver.SYS
2009-11-03 14:14 . 2009-11-03 15:00 -------- d-----w- c:\program files\AA
2009-11-03 12:46 . 2009-11-03 12:46 -------- d-----w- c:\documents and settings\Ton Warnaar\Local Settings\Application Data\Threat Expert
2009-11-03 12:35 . 2009-11-10 15:39 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-03 12:28 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-11-02 23:48 . 2009-11-02 23:48 -------- d-----w- c:\program files\Zeallsoft
2009-10-17 18:10 . 2009-10-17 18:10 -------- d-----r- c:\documents and settings\Ton Warnaar\Application Data\Brother
2009-10-16 13:24 . 2009-10-16 13:24 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-15 16:53 . 2009-10-15 16:53 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-15 16:37 . 2009-10-15 16:37 34308 ----a-w- c:\documents and settings\All Users\Application Data\mazuki.dll
2009-10-15 16:06 . 2009-10-15 16:06 -------- d-----w- c:\program files\Gabest
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-10 15:43 . 2003-04-08 12:00 594056 ----a-w- c:\windows\system32\perfh013.dat
2009-11-10 15:43 . 2003-04-08 12:00 110788 ----a-w- c:\windows\system32\perfc013.dat
2009-11-08 19:23 . 2009-11-08 19:23 -------- d-----w- c:\program files\Prevx
2009-11-08 19:23 . 2009-11-08 19:23 -------- d-----w- c:\program files\Common Files\Download Manager
2009-11-08 19:23 . 2009-11-08 16:47 -------- d-----w- c:\program files\Java
2009-11-08 19:23 . 2009-11-08 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-11-08 19:22 . 2009-11-08 17:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-08 18:00 . 2009-09-08 12:28 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\LimeWire
2009-11-08 17:35 . 2009-11-08 17:35 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\Malwarebytes
2009-11-08 17:35 . 2009-11-08 17:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-08 16:47 . 2009-09-09 14:25 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-08 16:46 . 2009-11-08 16:46 152576 ----a-w- c:\documents and settings\Ton Warnaar\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-08 16:31 . 2009-09-07 18:37 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\GrabIt
2009-11-05 17:20 . 2009-09-06 18:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-03 20:19 . 2009-09-07 19:54 -------- d-----w- c:\program files\Ashampoo
2009-10-22 11:10 . 2009-09-09 13:59 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-19 11:20 . 2009-10-02 12:03 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\Nero
2009-10-15 17:36 . 2009-10-02 11:46 -------- d-----w- c:\program files\Common Files\Nero
2009-10-15 17:29 . 2009-10-02 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-10-15 13:11 . 2009-10-15 13:11 -------- d-----w- c:\program files\SubSync
2009-10-15 13:11 . 2009-10-12 10:41 249856 ------w- c:\windows\Setup1.exe
2009-10-15 13:11 . 2009-10-12 10:41 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-10-12 10:41 . 2009-10-12 10:41 -------- d-----w- c:\program files\Brad Smith
2009-10-07 15:57 . 2009-10-07 15:45 57 ----a-w- c:\documents and settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_cat.bat
2009-10-07 15:51 . 2009-10-07 15:51 50 ----a-w- c:\windows\system32\bridf05a.dat
2009-10-07 15:51 . 2009-10-07 15:51 -------- d-----w- c:\program files\Brother
2009-10-07 15:51 . 2009-09-06 19:15 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-07 15:46 . 2009-10-07 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-10-07 15:46 . 2009-10-07 15:46 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2009-10-07 15:46 . 2009-10-07 15:46 -------- d-----w- c:\program files\ScanSoft
2009-10-07 15:46 . 2009-10-07 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-10-07 15:45 . 2009-10-07 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Brother
2009-10-05 19:35 . 2009-10-05 12:50 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\Skype
2009-10-05 19:32 . 2009-10-05 12:50 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\skypePM
2009-10-05 13:34 . 2009-10-03 22:06 -------- d-----w- c:\program files\SWF-AVI-GIF Converter
2009-10-05 12:50 . 2009-10-05 12:50 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-05 12:49 . 2009-10-05 12:49 -------- d-----r- c:\program files\Skype
2009-10-05 12:49 . 2009-10-05 12:49 -------- d-----w- c:\program files\Common Files\Skype
2009-10-05 12:49 . 2009-10-05 12:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-10-03 22:09 . 2009-10-03 22:09 -------- d-----w- c:\program files\ImTOO
2009-10-02 11:57 . 2009-10-02 11:46 -------- d-----w- c:\program files\Nero
2009-10-02 11:49 . 2009-10-02 11:46 -------- d-----w- c:\program files\DVDlabPro2
2009-10-02 10:50 . 2009-10-02 10:50 -------- d-----w- c:\program files\DVD Decrypter
2009-10-02 08:55 . 2009-10-02 08:20 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\ImgBurn
2009-10-02 08:06 . 2009-10-02 08:06 -------- d-----w- c:\program files\ImgBurn
2009-10-01 14:08 . 2009-10-01 14:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Hagel Technologies
2009-10-01 14:08 . 2009-10-01 14:08 -------- d-----w- c:\program files\DU Meter
2009-09-28 16:12 . 2009-09-28 16:12 -------- d-----w- c:\program files\Notuleren
2009-09-25 16:58 . 2009-09-16 19:36 2289152 ----a-w- c:\windows\system32\TUKernel.exe
2009-09-25 16:17 . 2009-09-25 16:17 -------- d-----w- c:\program files\MSXML 4.0
2009-09-24 19:00 . 2009-09-24 19:00 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\Samsung
2009-09-24 18:56 . 2009-09-24 18:40 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-09-24 18:39 . 2009-09-24 18:39 -------- d-----w- c:\program files\Samsung
2009-09-22 10:05 . 2009-09-22 10:05 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-19 09:46 . 2009-09-12 21:33 -------- d-----w- c:\program files\Kroll Ontrack
2009-09-17 11:51 . 2009-09-17 11:51 2373416 ----a-w- c:\documents and settings\All Users\Application Data\Nero\Nero 9\DrWeb\DrWeb32.dll
2009-09-17 11:47 . 2009-09-17 11:47 -------- d-----w- c:\program files\XviD
2009-09-17 11:42 . 2009-09-17 11:42 -------- d-----w- c:\program files\WinAVI Video Converter 9.0
2009-09-17 10:58 . 2009-09-17 10:58 2373416 ----a-w- c:\documents and settings\All Users\Application Data\Nero\Nero\DrWeb\DrWeb32.dll
2009-09-16 19:37 . 2009-09-16 19:37 5535744 ----a-w- c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe
2009-09-16 19:17 . 2009-09-16 19:17 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-16 19:17 . 2009-09-16 19:17 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-16 19:17 . 2009-09-15 16:04 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-09-16 17:51 . 2009-09-16 17:49 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\EditPlus 3
2009-09-15 16:43 . 2009-09-09 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-15 16:04 . 2009-09-15 16:04 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\TuneUp Software
2009-09-15 16:04 . 2009-09-15 16:04 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-09-15 16:04 . 2009-09-15 16:04 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-09-14 18:01 . 2009-09-14 18:01 -------- d-----w- c:\program files\Easy DVD Player
2009-09-14 15:52 . 2009-09-14 14:03 -------- d-----w- c:\documents and settings\Ton Warnaar\Application Data\VoipBuster
2009-09-14 10:31 . 2009-09-14 10:31 -------- d-----w- c:\program files\QuickPar
2009-09-12 20:57 . 2009-09-07 21:47 68456 ----a-w- c:\documents and settings\Ton Warnaar\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-12 10:32 . 2009-09-09 18:55 -------- d-----w- c:\program files\MSBuild
2009-09-12 10:32 . 2009-09-12 10:32 -------- d-----w- c:\program files\Reference Assemblies
2009-09-11 14:20 . 2008-04-14 20:32 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 13:54 . 2009-11-08 17:35 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 13:53 . 2009-11-08 17:35 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 19:27 . 2009-09-06 18:48 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-09-09 14:25 . 2009-09-07 19:56 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-06 19:15 . 2009-09-06 19:15 315392 ----a-w- c:\windows\HideWin.exe
2009-09-06 19:15 . 2009-09-06 19:16 86016 ----a-w- c:\windows\SoundMan.exe
2009-09-06 19:15 . 2009-09-06 19:16 1826816 ----a-w- c:\windows\SkyTel.exe
2009-09-06 19:15 . 2009-09-06 19:16 1191936 ----a-w- c:\windows\RtlUpd.exe
2009-09-06 19:15 . 2009-09-06 19:16 9715200 ----a-w- c:\windows\RTLCPL.exe
2009-09-06 19:15 . 2009-09-06 19:16 4419584 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-09-06 19:15 . 2009-09-06 19:16 16342528 ----a-w- c:\windows\RTHDCPL.exe
2009-09-06 19:15 . 2009-09-06 19:16 2162688 ----a-w- c:\windows\MicCal.exe
2009-09-06 19:15 . 2009-09-06 19:16 49152 ----a-w- c:\windows\system32\ChCfg.exe
2009-09-06 19:15 . 2009-09-06 19:16 69632 ----a-w- c:\windows\Alcmtr.exe
2009-09-06 19:15 . 2009-09-06 19:16 2808832 ----a-w- c:\windows\alcwzrd.exe
2009-09-06 19:15 . 2009-09-06 19:15 520192 ----a-w- c:\windows\RtlExUpd.dll
2009-09-06 18:44 . 2009-09-06 18:44 21748 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-04 21:05 . 2008-04-14 20:32 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:00 . 2008-04-14 20:32 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:02 . 2008-04-14 20:32 247326 ----a-w- c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2009-03-13 1058816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-23 8433664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-23 81920]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl05a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-05-17 933888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-05 1107848]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-08 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ioCentre
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipBuster
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Nero\\Nero 9\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 DiagnosticScan;DiagnosticScan;c:\windows\system32\drivers\DiagnosticScan.SYS [3-11-2009 15:14 16384]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5-11-2009 16:50 114768]
R1 Start1Driver;Start1Driver;c:\windows\system32\drivers\Start1Driver.SYS [3-11-2009 15:14 5120]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5-11-2009 16:50 20560]
R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe [1-10-2009 15:08 1391136]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [5-11-2009 20:22 337800]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [16-9-2009 20:17 604488]
R2 WDI;Windows Resident Anti-Virus;"c:\windows\System32\WinDefense32\wdi\svchost.exe" [4-11-2009 15:55 5634048]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\Drivers\gHidPnp.Sys --> c:\windows\system32\Drivers\gHidPnp.Sys [?]
S3 gMouPS2;PS2 Scroll Mouse Device;c:\windows\system32\DRIVERS\gMouPS2.sys --> c:\windows\system32\DRIVERS\gMouPS2.sys [?]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\DRIVERS\gMouUsb.sys --> c:\windows\system32\DRIVERS\gMouUsb.sys [?]
--- Andere Services/Drivers In Geheugen ---
*NewlyCreated* - MBR
*Deregistered* - mbr
*Deregistered* - mchInjDrv
*Deregistered* - PROCEXP113
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Inhoud van de 'Gedeelde Taken' map
2009-11-10 c:\windows\Tasks\1-klik Onderhoud.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 10:04]
.
.
------- Bijkomende Scan -------
.
uStart Page = hxxp://google.nl/
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS VERWIJDERD - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-10 16:49
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DUMeterSvc]
"ImagePath"="c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
Voltooingstijd: 2009-11-10 16:52
ComboFix-quarantined-files.txt 2009-11-10 15:52
Pre-Run: 40.113.684.480 bytes beschikbaar
Post-Run: 40.590.073.856 bytes beschikbaar
WindowsXP-KB310994-SP2-Pro-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=UX2VK0 /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=UX2VK0-BAK
- - End Of File - - A7E6728A68B4AF2D6666C0A079C16981